Attackers are tricking Minecraft players into downloading malware by impersonating popular Minecraft clients and resellers in Google search results. Even after the campaign’s command-and-control infrastructure was taken down, the operation continued by shifting distribution to common file-hosting platforms like Discord, MediaFire, GitHub, and Dropbox.
Key findings
- McAfee observed ongoing activity from the WeedHack campaign after an earlier takedown of its command-and-control infrastructure.
- Attackers used SEO poisoning and fake websites impersonating legitimate Minecraft clients to put malicious downloads in front of gamers.
- The campaign shifted to distributing malware via mainstream file-hosting services, especially Discord, plus MediaFire, GitHub, and Dropbox.
- Some fake sites lured users with offers like free versions of paid tools or cracked software.
Who’s being targeted
- Commonly targeted roles: Gamers/Players, Students, Helpdesk/IT support (endpoint protection guidance), Parents/Guardians (home device safety).
- Affected industries: Gaming, Consumer/End users, Education (students/gamers).
- Attack channels: website, discord.
- Impersonated: Legitimate Minecraft client/reseller site (e.g., a popular client such as “Xenon Client”), A Minecraft mod/client uploader using Discord file hosting.
Awareness takeaways
- Only download mods/clients/tools from trusted, official sources (not “top Google results” or lookalike sites).
- Be skeptical of “free” offers for paid tools/cracked software, these are common bait for malware.
- Keep security software enabled and scan downloads before opening them.
- Check links carefully for lookalike domains before downloading anything.
Red flags to watch for
- Arrives via a lookalike website that imitates a known Minecraft client/reseller
- Promotes “free versions of paid tools” or “cracked software” as a lure
- Download is pushed via search results influenced by SEO manipulation
- Uses a general-purpose file-hosting link instead of an official project site
- Unexpected executable download for a “client/mod”
- Link origin does not match the official source for the tool
Read the video transcript
You Google a Minecraft client like “Xenon Client” and click the top result, without thinking. That’s the WeedHack trap. WeedHack uses SEO poisoning and lookalike Minecraft client sites that promise free or cracked tools. You click download…and the file actually comes from Discord, MediaFire, GitHub, or Dropbox, not the real project site. Here’s the tell: a “free” version of a paid Minecraft tool, hosted on a generic link like Discord or MediaFire, and the URL doesn’t match the official client site. If the download is an unexpected EXE for a mod, that’s your red flag. One move: only download Minecraft clients and mods from the official project site you type in yourself, then let your security software scan the file before you run it.